[EXPL] ArGoSoft FTP Server Buffer Overflow Exploit (DELE)

From: SecuriTeam (support_at_securiteam.com)
Date: 04/05/05

  • Next message: SecuriTeam: "[UNIX] Sybase ASE Multiple Security Issues"
    To: list@securiteam.com
    Date: 5 Apr 2005 16:44:18 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      ArGoSoft FTP Server Buffer Overflow Exploit (DELE)
    ------------------------------------------------------------------------

    SUMMARY

     <http://www.argosoft.com/> ArGoSoft FTP Server is "a lightweight FTP
    Server for Microsoft Windows platforms"

    ArGoSoft FTP server contains a remote buffer overflow in the DELE (delete)
    command, that may cause execution of arbitrary machine code. The following
    exploit is a proof of concept to the previously mentioned buffer overflow
    vulnerability in ArGoSoft FTP Server.

    DETAILS

    Vulnerable Systems:
     * ArGoSoft versions 1.4.2.29 and prior

    Exploit:
    /*
      ArGoSoft Ftp Server remote overflow exploit
      author : c0d3r "kaveh razavi" c0d3rz_team@yahoo.com c0d3r@ihsteam.com
      package : ArGoSoft 1.4.2.29 and prior
      advisory : packetstormsecurity.nl/0503-advisories/argosoftFTP1428.txt
      company address : argosoft.com
      the bug was found by a mate and reported to argosoft and they released
      another version . I downloaded the patched ver at www.argosoft.com
      and started to test the server . I saw that they worked with the vul
      but they didnt solve the mentioned DELE overflow . he did a wise job
      every long char which would be send to server it will write a nullbyte
      in the middle so we cant overwrite eip or other registers normally .
      The eip would be overwrite like 00410041 which seems useless . the
    server
      wont crash but it shows that it has beed overflowed . but the program
    maker
      doesnt think there are people who can do wiser job ! well there is a way
    to
      get shell.I just mention it.the code below is just show that the server
    is vuln.
      we can overwrite eip with a nullbyte without sending a null !!!
      so think there is a jmp call pop push register is around 004400E1 (for
    example)
      so we can directly jmp to anywhere we want . anyway if u want u can try

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[UNIX] Sybase ASE Multiple Security Issues"

    Relevant Pages

    • [EXPL] ArGoSoft FTP Server Remote Buffer Overflow Exploit
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... ArGoSoft FTP Server Remote Buffer Overflow Exploit ... commands, and much more, such as passive mode, resuming file transfers, ...
      (Securiteam)
    • [NT] ArGoSoft FTP Server DELE Buffer Overflow
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... ArGoSoft FTP Server DELE Buffer Overflow ... commands, and much more, such as passive mode, resuming file transfers, ...
      (Securiteam)
    • [NT] ArGoSoft FTP Server XCMD Buffer Overflow
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... ArGoSoft FTP Server is ...
      (Securiteam)
    • [NT] Buffer Overflow in ArGoSoft FTP (DELE)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... ArGoSoft FTP Server is "a lightweight FTP ... ArGoSoft FTP server contains a remote buffer overflow in the DELE ...
      (Securiteam)
    • [NT] HP Radia Notify Daemon Multiple Buffer Overflows
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... RADEXECD process with parameters of a greater length than the buffer used ... structures, executes the target process, and waits for it to terminate. ... text:0040619E call _strcpy; overflow here ...
      (Securiteam)